Google patches a CVSS 10 Gemini CLI vulnerability that allowed hackers to use prompt injection and privilege escalation for a full supply chain compromise.
A vulnerability, which was classified as problematic, has been found in jupyter notebook up to 7.5.5. The affected element is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-40171. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in OpenMRS up to 2.7.8/2.8.5. Impacted is the function WebModuleUtil.startModule of the file /openmrs/ws/rest/v1/module of the component REST Endpoint. Such manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-40076. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in QuantumNous new-api. This issue affects some unknown processing. This manipulation causes server-side request forgery.
This vulnerability is tracked as CVE-2026-42339. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability described as critical has been identified in dssrf. This vulnerability affects the function is_url_safe of the component IPv6 Category Handler. The manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2026-44232. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability labeled as problematic has been found in ZTE ZXHN H298A 1.1. Affected by this issue is some unknown functionality of the component Router Web Interface. Executing a manipulation can lead to information disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2026-34474. The attack may be launched remotely. There is no exploit available.
A vulnerability identified as problematic has been detected in HCL BigFix Service Management 23. Affected by this vulnerability is an unknown functionality. Performing a manipulation of the argument consumer_company results in information exposure through error message.
This vulnerability was named CVE-2025-31960. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as problematic has been discovered in HCL BigFix Service Management 23. Affected is an unknown function. Such manipulation leads to sensitive information in log files.
This vulnerability is uniquely identified as CVE-2024-30151. The attack can be launched remotely. No exploit exists.
A vulnerability was found in HCL BigFix Service Management 23. It has been rated as problematic. This impacts an unknown function. This manipulation causes insecure default initialization of resource.
This vulnerability is handled as CVE-2025-31974. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in lepture mistune up to 3.2.0. It has been declared as problematic. This affects an unknown function of the component Markdown Parser. The manipulation results in inefficient regular expression complexity.
This vulnerability is known as CVE-2026-33079. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in givanz Vvveb up to 1.0.8.2. It has been classified as problematic. The impacted element is an unknown function. The manipulation leads to insecure default initialization of resource.
This vulnerability is traded as CVE-2026-41931. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in givanz Vvveb up to 1.0.8.1 and classified as problematic. The affected element is an unknown function of the component Tools/Import. Executing a manipulation can lead to xml external entity reference.
This vulnerability appears as CVE-2026-41936. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. This issue affects some unknown processing. Such manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2026-0300. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability, which was classified as critical, has been found in givanz Vvveb up to 1.0.8.1. This vulnerability affects unknown code. This manipulation causes unrestricted upload.
This vulnerability is registered as CVE-2026-41938. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in givanz Vvveb up to 1.0.8.1. This affects an unknown part. The manipulation results in incomplete blacklist.
This vulnerability is cataloged as CVE-2026-41934. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in givanz Vvveb up to 1.0.8.1. Affected by this issue is some unknown functionality. The manipulation leads to missing authentication.
This vulnerability is listed as CVE-2026-41930. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Google Chrome on Windows. Affected by this vulnerability is an unknown functionality of the component Chromoting. Executing a manipulation can lead to race condition.
This vulnerability is tracked as CVE-2026-7948. The attack is restricted to local execution. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Google Chrome. Affected is an unknown function of the component MHTML. Performing a manipulation results in HTML injection.
This vulnerability is identified as CVE-2026-8012. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.